Usable with caveats: it is actively maintained and clearly documented, with organization backing, tests, and a clean release setup. It is only 47 days old, releases arrive roughly every four hours, and 80% of recent commits come from one of two contributors; the repository also lacks a security policy and explicit workflow permissions.
72%
Total Score
88
50
88
80
Five runtime dependencies, including framework, authentication, and identity components, create meaningful compatibility and transitive-maintenance exposure for this security-sensitive API package.
The package is only 47 days old and has 11 releases, with a median interval of roughly four hours. This shows active iteration but provides little evidence of long-term stability.
Two contributors are active, but the leading contributor made 80% of recent commits. Organization backing partly compensates for this concentration, but individual-maintainer dependence remains a concern.
Composer build tooling is present, but no security scanning tools were detected. For a package handling tokens and service identities, that is a meaningful transparency and assurance gap.
The repository has no security policy. That leaves disclosure and response expectations unclear for a package whose stated scope includes tokens, expiry, and revocation.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/sanctum Version ^4.0 | — | — |
illuminate/support Version ^13.0 | — | — |
illuminate/database Version ^13.0 | — | — |
liberusoftware/identity-core Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.